Privacy Policy
Version v1.1Effective from: 2026-09-30
This policy explains what data is collected when you use MakinAI, why it is processed and how long it is kept. A detailed data protection notice is published separately.
1. Data controller
The data controller is Mustafa Güldüler, owner of the sole proprietorship (without a trade name) that operates the MakinAI platform; address: Tunalı Mah. Yenibahçe Sk. Aktaş Dilan Apt. No: 2 İç Kapı No: 1, Tepebaşı / Eskişehir. You can send your requests to [email protected].
2. Data we process
Account data: full name, e-mail, phone number, password hash, account type and, for corporate accounts, company details.
Listing data: machine specifications, price, location (province/district), photographs and the machine type plate image.
Transaction data: listing views, phone reveal counters, enquiry and request records, order and invoice records.
Technical data: session cookie, language preference cookie, browser/operating system information and server access logs. IP addresses are stored HASHED for rate limiting and abuse analysis; they are not kept in plain text.
3. Purposes of processing
Membership and session management; publishing, verifying and moderating listings; enabling buyers and sellers to make contact; collecting listing and plan fees and issuing invoices; rate limiting, fraud and abuse detection; improving the service and debugging; complying with legal obligations.
Marketing messages are only sent with your separate, explicit consent, which you can withdraw at any time with a single click.
5. Data residency
The database, media files and backups are hosted in Türkiye or the European Union. The only exception is the masked text sent to AI providers described above.
6. Retention periods
Active account data is kept for as long as the account is open. Accounts with no sign-in for 24 months are anonymised after a warning.
Withdrawn listings and listing media are deleted or turned into anonymous statistics after 12 months. Messages are anonymised after 24 months. Server access logs are deleted after 12 months and masked AI request logs after 6 months.
Payment, invoice and accounting records are kept for 10 years as required by law, consent records for 10 years for evidentiary purposes, and audit logs for 5 years.
7. Security
Passwords are stored only as hashes. Session tokens are signed. Endpoints such as sign-in, registration, verification codes and the contact form are rate limited.
Uploaded photographs are re-encoded; location (GPS) and device metadata are STRIPPED automatically.
Access rights are reviewed regularly, and operations that touch personal data are written to an audit log.
8. Your rights
You have the right to access, rectify and erase your personal data, to object to processing and to data portability. Requests are answered within 30 days at the latest.
For a detailed explanation and the application procedure, see the data protection notice.
Related documents
You can save this page as a PDF with your browser’s print function.